2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9417 | HIGH | 8.8 | 0.4% | Aug 25, 2025 | A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processi... |
| CVE-2025-57811 | HIGH | 7.2 | 0.8% | Aug 25, 2025 | Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is... |
| CVE-2025-57802 | HIGH | 8.7 | 0.4% | Aug 25, 2025 | Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. ... |
| CVE-2025-50383 | HIGH | 8.1 | 0.4% | Aug 25, 2025 | alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by paramet... |
| CVE-2025-6737 | HIGH | 7.2 | 0.2% | Aug 25, 2025 | Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenan... |
| CVE-2025-57760 | HIGH | 8.8 | 0.4% | Aug 25, 2025 | Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exis... |
| CVE-2025-29421 | HIGH | 7.5 | 0.3% | Aug 25, 2025 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function. |
| CVE-2025-29420 | HIGH | 7.5 | 0.8% | Aug 25, 2025 | PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function. |
| CVE-2025-55409 | HIGH | 8.8 | 0.5% | Aug 25, 2025 | FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbi... |
| CVE-2025-53119 | HIGH | 7.5 | 11.0% | Aug 25, 2025 | An unauthenticated unrestricted file upload vulnerability allows an attacker to upload malicious binaries and scripts to... |
| CVE-2025-3478 | HIGH | 8.5 | 0.3% | Aug 25, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Enterprise Security Manager. The vulne... |
| CVE-2025-29523 | HIGH | 7.2 | 2.1% | Aug 25, 2025 | D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 was discovered to contain a command injection vulnerability vi... |
| CVE-2025-5302 | HIGH | 8.6 | 0.3% | Aug 25, 2025 | A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifical... |
| CVE-2025-56216 | HIGH | 8.5 | 0.3% | Aug 25, 2025 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter. |
| CVE-2025-53510 | HIGH | 8.8 | 0.6% | Aug 25, 2025 | A memory corruption vulnerability exists in the PSD Image Decoding functionality of the SAIL Image Decoding Library v0.9... |
| CVE-2025-53085 | HIGH | 8.8 | 0.7% | Aug 25, 2025 | A memory corruption vulnerability exists in the PSD RLE Decoding functionality of the SAIL Image Decoding Library v0.9.8... |
| CVE-2025-52930 | HIGH | 8.8 | 0.7% | Aug 25, 2025 | A memory corruption vulnerability exists in the BMPv3 RLE Decoding functionality of the SAIL Image Decoding Library v0.9... |
| CVE-2025-52456 | HIGH | 8.8 | 0.6% | Aug 25, 2025 | A memory corruption vulnerability exists in the WebP Image Decoding functionality of the SAIL Image Decoding Library v0.... |
| CVE-2025-51281 | HIGH | 7 | 0.4% | Aug 25, 2025 | D-Link DI-8100 16.07.26A1 is vulnerable to Buffer Overflow via the en`, `val and id parameters in the qj_asp function. T... |
| CVE-2025-50129 | HIGH | 8.8 | 0.7% | Aug 25, 2025 | A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9... |
| CVE-2025-46407 | HIGH | 8.8 | 0.6% | Aug 25, 2025 | A memory corruption vulnerability exists in the BMPv3 Palette Decoding functionality of the SAIL Image Decoding Library ... |
| CVE-2025-35984 | HIGH | 8.8 | 0.9% | Aug 25, 2025 | A memory corruption vulnerability exists in the PCX Image Decoding functionality of the SAIL Image Decoding Library v0.9... |
| CVE-2025-32468 | HIGH | 8.8 | 0.6% | Aug 25, 2025 | A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0... |
| CVE-2025-54370 | HIGH | 8.7 | 0.7% | Aug 25, 2025 | PhpOffice/PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to versions 1.30.0, 2.1.... |
| CVE-2025-43960 | HIGH | 8.6 | 0.7% | Aug 25, 2025 | Adminer 4.8.1, when using Monolog for logging, allows a Denial of Service (memory consumption) via a crafted serialized ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now